VDB
CVE-2015-3240
CVE-2015-3240
PUBLISHED
CVSS 4.300000190734863 MEDIUM
The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of service (assertion failure and daemon restart) via a zero DH g^x value in a KE payload in a IKE packet.
EPSS 2.79% · 85.9th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
2.79%
85.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| libreswan | libreswan | 3.14 |
Timeline
- Nov 3, 2015 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Feb 10, 2023 EPSS Score
- Feb 13, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 27, 2023 EPSS Score
- Jul 19, 2023 EPSS Score
References
- RHSA-2015:1979 vendor-advisory
- 1033418 vdb
- http://www.securityfocus.com/bid/77536 technical
- https://lists.openswan.org/pipermail/users/2015-August/023401.html advisory
- https://nvd.nist.gov/vuln/detail/CVE-2015-3240 advisory
- https://access.redhat.com/errata/RHSA-2015:1979 url
- https://access.redhat.com/security/cve/CVE-2015-3240 url
- https://bugzilla.redhat.com/show_bug.cgi?id=1232320 url
- https://libreswan.org/security/CVE-2015-3240 url
- https://libreswan.org/security/CVE-2015-3240/CVE-2015-3240.txt url
- https://security.gentoo.org/glsa/201603-13 url
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html url